Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2p4v-77rh-r7fj

около 4 лет назад

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p4r-xjwx-3whg

около 2 лет назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2p4r-h63c-pgmr

около 2 лет назад

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2p4q-qchf-h9q6

5 месяцев назад

A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2p4q-qc9j-27gx

больше 1 года назад

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p4q-q7j4-q23g

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check BIOS images before it is used BIOS images may fail to load and null checks are added before they are used. This fixes 6 NULL_RETURNS issues reported by Coverity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p4q-pg24-pmp6

около 4 лет назад

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.

EPSS: Низкий
github логотип

GHSA-2p4q-mvv4-rjr2

около 1 года назад

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2p4m-4mc7-m8w7

5 месяцев назад

A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2p4j-rf5v-mxpv

4 месяца назад

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p4j-8pc7-8jg8

больше 4 лет назад

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.

EPSS: Низкий
github логотип

GHSA-2p4j-7hmq-hf5r

11 месяцев назад

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p4j-3h9f-v3pj

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2p4h-vppg-wjv6

5 месяцев назад

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2p4h-6x4f-47jj

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p4g-jrmx-r34m

около 4 лет назад

Rancher Login Parameter Can Be Edited

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2p4f-vc9q-r5vp

около 2 лет назад

Typo3 Arbitrary file upload and XML External Entity processing

EPSS: Низкий
github логотип

GHSA-2p4f-q7g6-g44m

около 4 лет назад

A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.

EPSS: Низкий
github логотип

GHSA-2p4f-5m6f-7653

больше 4 лет назад

GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

EPSS: Низкий
github логотип

GHSA-2p49-hgcm-8545

13 дней назад

SVGO removeScripts plugin leaves some executable scripts intact

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p4v-77rh-r7fj

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2p4r-xjwx-3whg

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2p4r-h63c-pgmr

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2p4q-qchf-h9q6

A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-2p4q-qc9j-27gx

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2p4q-q7j4-q23g

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check BIOS images before it is used BIOS images may fail to load and null checks are added before they are used. This fixes 6 NULL_RETURNS issues reported by Coverity.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2p4q-pg24-pmp6

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2p4q-mvv4-rjr2

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2p4m-4mc7-m8w7

A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2p4j-rf5v-mxpv

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2p4j-8pc7-8jg8

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2p4j-7hmq-hf5r

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2p4j-3h9f-v3pj

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p4h-vppg-wjv6

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database.

CVSS3: 8.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-2p4h-6x4f-47jj

Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-2p4g-jrmx-r34m

Rancher Login Parameter Can Be Edited

CVSS3: 4.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-2p4f-vc9q-r5vp

Typo3 Arbitrary file upload and XML External Entity processing

около 2 лет назад
github логотип
GHSA-2p4f-q7g6-g44m

A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p4f-5m6f-7653

GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2p49-hgcm-8545

SVGO removeScripts plugin leaves some executable scripts intact

CVSS3: 8.2
13 дней назад

Уязвимостей на страницу